<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA authentication issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-issue/m-p/2174046#M137916</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you seeing any logs on the ACS? Which version of ACS are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also verify if the ASA has been added as the aaa client on the secondory ACS box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you have console access to the ASA you can verify aaa authetication with below commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;test aaa-server authentication ACS username xxxx password xxxx&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Please rate when applicable or helpful !!!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Mar 2013 05:55:11 GMT</pubDate>
    <dc:creator>kcnajaf</dc:creator>
    <dc:date>2013-03-18T05:55:11Z</dc:date>
    <item>
      <title>AAA authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-issue/m-p/2174045#M137895</link>
      <description>&lt;P&gt;Dear All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am running ASA5520 security appliance and have trouble to login to this device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have used 2 ACS servers for example xxx.xxx.xxx.xxx and yyy.yyy.yyy.yyy&lt;/P&gt;&lt;P&gt;first priority is xxx.xxx.xxx.xxx and yyy.yyy.yyy.yyy is backup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;recently we have removed xxx.xxx.xxx.xxx ACS server and running only yyy.yyy.yyy.yyy server for authentication&lt;/P&gt;&lt;P&gt;but after remove primary ACS server, i can not login to the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;real configuration is as below&lt;/P&gt;&lt;P&gt;aaa-server TACACS_NETWORK protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server ACS protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server ACS (inside) host xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;key xxxxxxxx&lt;/P&gt;&lt;P&gt;aaa-server ACS (inside) host yyy.yyy.yyy.yyy&lt;/P&gt;&lt;P&gt;key yyyyyyyy&lt;/P&gt;&lt;P&gt;aaa authentication telnet console ACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console ACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console ACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console ACS LOCAL&lt;/P&gt;&lt;P&gt;aaa local authentication attempts max-fail 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think that my account should be authenticated using secondary ACS server yyy.yyy.yyy.yyy&lt;/P&gt;&lt;P&gt;but failed.&lt;/P&gt;&lt;P&gt;somebody help me to fix this issue or if password recovery is necessary, could you please summarize brief step??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-issue/m-p/2174045#M137895</guid>
      <dc:creator>rcsco2011</dc:creator>
      <dc:date>2019-03-11T03:12:37Z</dc:date>
    </item>
    <item>
      <title>AAA authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-issue/m-p/2174046#M137916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you seeing any logs on the ACS? Which version of ACS are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also verify if the ASA has been added as the aaa client on the secondory ACS box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you have console access to the ASA you can verify aaa authetication with below commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;test aaa-server authentication ACS username xxxx password xxxx&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Please rate when applicable or helpful !!!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 05:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-issue/m-p/2174046#M137916</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2013-03-18T05:55:11Z</dc:date>
    </item>
    <item>
      <title>AAA authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-issue/m-p/2174047#M137966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all verify that your ASA is failing over to the secondary server upon&amp;nbsp; no response from the primary.&lt;/P&gt;&lt;P&gt;You can run tacacs+ debugs while trying to authenticate .&lt;/P&gt;&lt;P&gt;Also you need to check the ACS logs to verify if there is any attempt from your ASA.&lt;/P&gt;&lt;P&gt;Sometimes if you forgot to add your ASA as aaa client you might see messages&lt;/P&gt;&lt;P&gt;indicating bad request from Unknown NAS, this should give you a powerful indicator&lt;/P&gt;&lt;P&gt;that you need to add the ASA as AAA client. Sometimes there&amp;nbsp; might be an issue &lt;/P&gt;&lt;P&gt;with the shared key , so you have to make sure that the shared key for your ASA on&lt;/P&gt;&lt;P&gt;the secondary is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please make sure to rate correct answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 06:31:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-issue/m-p/2174047#M137966</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-18T06:31:20Z</dc:date>
    </item>
  </channel>
</rss>

